Keyboard shortcuts

Press ← or → to navigate between chapters

Press S or / to search in the book

Press ? to show this help

Press Esc to hide this help

DNS providers & credentials

The managed-DNS providers boatramp drives directly, and the manual fallback. Ten providers are built in. Each entry lists the value passed to --provider, any accepted alias, and the exact credential environment variables the provider reads.

Credentials are read from the environment only — never from a config file. The same --provider names apply in every DNS command surface: boatramp dns --provider <name>, boatramp serve --acme-dns-provider <name>, and boatramp domain add --provider <name>.

Providers

--providerAliasProviderCredential env vars
manual—none (prints records)—
cloudflare—CloudflareCLOUDFLARE_ZONE_ID, CLOUDFLARE_API_TOKEN
route53—AWS Route 53ROUTE53_HOSTED_ZONE_ID + the standard AWS chain
oci—Oracle Cloud DNSOCI_REGION, OCI_ZONE, OCI_KEY_ID, OCI_PRIVATE_KEY_FILE
digitaloceandoDigitalOceanDIGITALOCEAN_DOMAIN, DIGITALOCEAN_TOKEN
hetzner—Hetzner DNSHETZNER_ZONE_ID, HETZNER_ZONE, HETZNER_DNS_TOKEN
ns1—NS1 (IBM)NS1_ZONE, NS1_API_KEY
dnsimple—DNSimpleDNSIMPLE_ACCOUNT_ID, DNSIMPLE_ZONE, DNSIMPLE_TOKEN
gcp-dnsgcpGoogle Cloud DNSGCP_DNS_PROJECT, GCP_DNS_ZONE, GCP_ACCESS_TOKEN
azure-dnsazureAzure DNSAZURE_SUBSCRIPTION_ID, AZURE_RESOURCE_GROUP, AZURE_DNS_ZONE, AZURE_ACCESS_TOKEN
akamai—Akamai Edge DNSAKAMAI_HOST, AKAMAI_CLIENT_TOKEN, AKAMAI_CLIENT_SECRET, AKAMAI_ACCESS_TOKEN, AKAMAI_ZONE

Notes

  • manual prints the records to apply by hand and reads no credentials. It is the fallback for self-hosted authoritative servers (BIND, PowerDNS, Knot).
  • gcp-dns and azure-dns take a short-lived OAuth2 access token in GCP_ACCESS_TOKEN / AZURE_ACCESS_TOKEN. Mint it with gcloud / az.
  • route53 reads ROUTE53_HOSTED_ZONE_ID for the zone and resolves credentials through the standard AWS provider chain (environment, shared config, instance role).

See also